Vulnerability Description
Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing user´s password by adding a 6-digit numeric token. An attacker could create an automatic script to test all possible values because the platform has no limit on the number of requests.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Password Recovery Project | Password Recovery | 1.2 |
Related Weaknesses (CWE)
References
- https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-rounThird Party Advisory
- https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-rounThird Party Advisory
FAQ
What is CVE-2023-3222?
CVE-2023-3222 is a vulnerability with a CVSS score of 7.5 (HIGH). Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing user´s password by adding a 6-...
How severe is CVE-2023-3222?
CVE-2023-3222 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-3222?
Check the references section above for vendor advisories and patch information. Affected products include: Password Recovery Project Password Recovery.